Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-23 · updated: 2026-09-23 · tags: [incident, retail, macos] · confidence: high · severity: low · affected_sectors: [retail] · au_impact: false

Security researcher Patrick Wardle has published a proof of concept showing that malware already running as the logged-in macOS user can quietly take over Meta's Muse assistant by redirecting where it sends dictated prompts. The mechanism is an undocumented application preference, endo_voyager_dictation_endpoint, which any process running as that user can repoint at an attacker-controlled address without additional permissions. From there Wardle demonstrated three consequences: reading what the user dictated, injecting extra instructions that Muse treats as trusted, and capturing the account token — which matters because a Muse account can be signed in on multiple devices, so a stolen token lets the attacker direct the assistant beyond the compromised Mac. Muse is the personal AI agent Meta launched this month in the United States; it works across files, email, messages, the calendar, shopping and smart-home apps, using whatever access the user grants, and Wardle's argument is that this is exactly why it is a target: macOS Data Protection normally limits what malware can reach, and steering a signed app with broad permissions bypasses that limit without triggering security tooling, because the commands come from an app the user trusted. He also notes a remote attacker could deliver it through a ClickFix-style trick. Wardle's advice is blunt: do not install Muse.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-09-23
Source The Register
Reliability Tier 3